Security & Authentication

Sign-in methods, passkeys, 2FA, recovery codes, and signed-in devices.

Keeping your account secure helps protect your workspace, your projects, and your team's data.

Trellis supports multiple sign-in methods, two-factor authentication (2FA), passkeys, and recovery codes — giving you flexible ways to access your account while keeping it protected.

Sign-in methods

Sign-in methods are how you log in to your Trellis account. You can use email and password, Google, or Microsoft. Linking more than one gives you a fallback if one becomes unavailable, so you don't get locked out.

You'll always need at least one active sign-in method. Once you have more than one, use the three-dot menu next to any method to remove it.

Passkeys (our strong recommendation)

Give each passkey a recognisable name (e.g. MacBook Pro) so you know which device you're removing later. Use the three-dot menu next to any passkey to rename or remove it.

Two-factor authentication

Every Trellis account has two-factor authentication (2FA) on by default. It's set up during onboarding and can't be turned off, since it's the strongest protection against someone signing in as you if they get hold of your password.

If you lose access to your authenticator app, use one of your recovery codes to sign back in.

Recovery codes

Recovery codes are one-time backup codes that let you sign in when your authenticator app isn't available (lost phone, new device, app reset). Store them somewhere secure like a password manager.

Regenerate your codes at any time. The moment you do, the previous set stops working, so download or copy the new set straight away.

Signed-in devices

See every device currently signed in to your Trellis account, along with its location, browser, and last activity. Expand any row to see full details.

Review this list regularly. If you see a device you don't recognise, use Revoke access on that row straight away — or Sign out of all other devices to clear every session except your current one in one go.

Who can do what

ActionOwnerAdminEditorMemberContributorViewer
Manage your own sign-in methods, passkeys, recovery codes, and devices

Security settings apply to your Trellis account, not a specific workspace, so every role has the same access to their own security controls. Your choices only affect how you access your account and don't change anything for other members.